Legal
Privacy policy
Your journal is private by default. You choose what leaves it. This page says exactly what that means.
Who we are
Slowburn is made and operated by Eriksen ENK, trading as Slowburn, a sole proprietorship (enkeltpersonforetak) registered in Norway, organisation number 937 027 834. For anything about this policy, write to [email protected]. Under European data protection law we are the controller of the data described below.
The short version
- Your reading journal — shelf, progress, ratings, spice, moods, tropes, notes, saved lines, burns, statistics and monthly dossiers — is stored on your phone and is never uploaded to us.
- If you create a circle, the things you deliberately share with it are stored on our servers so the people you chose can receive them. Nothing else from your journal is.
- We receive anonymous usage counts and crash reports through Google Firebase. They carry an app-install identifier, no account, and never a book, a rating, a note or anything anyone wrote.
- Purchases go through Apple or Google and RevenueCat. We never see your payment details.
- You can delete your circle and sign-in account yourself, in the app, at any time.
What stays on your phone
Everything you write or record about your reading: your shelf and the books on it, reading status and progress, ratings, personal spice, moods and tropes, private notes, saved lines, the Burn, finish dates, your statistics, Reading Identity, Compare and the Monthly Post-Mortem, cached book covers and catalogue snapshots. This data lives in a database on your device. Slowburn has no copy of it and no way to read it. It is included in your phone’s own backup (iCloud or Google) under your phone’s settings, not ours. If you delete the app, or use Erase everything on this phone, it is gone.
What we store on our servers, and only if you create a circle
The circle is the social part of Slowburn, and it is optional. If you create one, our servers (Cloudflare Workers and D1, hosted by Cloudflare) store:
- a sign-in account: an anonymous identifier issued by Firebase Authentication, and, if you choose to protect your circle, the link to your Apple or Google sign-in (we receive the identifier and, from Apple, the name and email you allow — used only to sign you in);
- your handle and identity, which are separate from your journal;
- your connections to the people you invited or who invited you;
- the entries you deliberately share with your circle (a book, a verdict, a month, a burn), and reactions and replies to them;
- Buddy Reads: the book, each reader’s position, and the notes you leave for the other reader;
- blocks and reports you make, and reports made about content you shared, with a snapshot of the reported content as evidence;
- your Shape Slowburn votes and ideas, if you take part;
- a push notification token for your device, so notifications can be delivered. Notifications never contain what you or anyone else wrote; they carry a reference to a screen in the app.
Nothing you share is public. Only the people in your circle, or the one person in a Buddy Read, receive it.
Who else receives data, and what
| Service | What it receives | Why |
|---|---|---|
| Google Firebase Analytics | Which screens and features are used, how long steps take, coarse bands (for example a reading-volume band), and closed lists of outcomes. Tied to an app-install identifier, not to an account. Advertising features and ad personalisation are switched off. | To see which parts of the app are used and where people get stuck. |
| Google Firebase Crashlytics | Crash reports with device and app version, and a trail of event names and screen names. Never the contents of any screen. | To find and fix crashes. |
| Google Firebase Authentication | An anonymous sign-in, and your Apple or Google sign-in if you protect your circle. | To know which circle is yours, and to let it survive a new phone. |
| Cloudflare | The circle data listed above, and, as with any web service, the network address of your requests, for security and rate limiting. | To run the circle. |
| RevenueCat | An anonymous app user identifier and your subscription status from Apple or Google. Slowburn never links it to your name or email. | To know whether Premium is active, and to restore purchases. |
| Apple App Store / Google Play | Your purchase, handled entirely by them. We never receive payment details. | To sell Premium. |
| Expo push service, Apple and Google notification services | Your device’s push token and the notification payload (a reference to a screen, never content). | To deliver notifications you turned on. |
| Open Library | The title, author or ISBN you type or scan when adding a book, and one request for its cover at the moment you save it. | To find books. Covers are fetched once and stored on your phone; the app never asks a third party for a cover while you browse your shelf. |
We do not use advertising identifiers, do not track you across other apps or sites, and do not sell or share data for advertising.
What analytics never contains
No book title, author or ISBN. No cover. No rating, spice, mood or trope. No note, saved line or reply. No handle or name. No shelf contents, finish dates or free text of any kind. This is enforced by automated tests in the app’s source code, not only by policy. The app tells you the same thing in Settings.
Why we process this data
Running the circle and Buddy Reads you asked for, and delivering Premium you bought, is performance of our agreement with you. Anonymous usage and crash reporting rest on our legitimate interest in keeping the app working and improving it, weighed against the fact that they contain nothing about your reading. Notifications are sent only with your permission, which you can withdraw in your phone’s settings at any time.
How long we keep it
- Circle data: until you delete your circle, or until we remove it under the community rules.
- Push tokens: until you turn notifications off, delete your circle, or the token stops working.
- Moderation evidence: a snapshot taken when content is reported is kept for safety review only and deleted 90 days after the review is finished. Open reports are kept until reviewed. This snapshot is not deleted instantly when the author deletes their account.
- After you delete your circle, a hashed marker of the deleted account is kept briefly so that a sign-in token still in flight cannot recreate it.
- Analytics and crash data: kept by Google under the retention period set in our Firebase project.
Your rights and your controls
You can delete your circle and sign-in account yourself in the app: here is how, including what remains afterwards. You can block or remove anyone from your circle, and report content. You can turn each kind of notification off in Settings, or all of them in your phone’s settings. Where European data protection law applies, you also have the rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to a supervisory authority; in Norway that is Datatilsynet. Write to us to exercise any of them. Because your journal is on your phone and not with us, access and portability of the journal itself are things you already have.
Children
Slowburn is a journal for romance readers, including books with explicit content, and is not intended for children under 16. We do not knowingly collect data from them.
Changes
If this policy changes in a way that matters, the app will tell you before the change applies. The date at the top is the date of the current version.